CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 129 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27472 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. | ||
| CVE-2022-27165 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus | ||
| CVE-2022-27164 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers | ||
| CVE-2022-27163 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser | ||
| CVE-2022-27162 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser | ||
| CVE-2022-27161 | Cri | 0.64 | 9.8 | 0.01 | Apr 12, 2022 | Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers | ||
| CVE-2021-37291 | Cri | 0.64 | 9.8 | 0.07 | Apr 11, 2022 | An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php. | ||
| CVE-2022-0949 | Cri | 0.64 | 9.8 | 0.08 | Apr 11, 2022 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to… | ||
| CVE-2022-27126 | Cri | 0.64 | 9.8 | 0.01 | Apr 10, 2022 | zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php. | ||
| CVE-2022-28001 | Cri | 0.64 | 9.8 | 0.02 | Apr 8, 2022 | Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter. | ||
| CVE-2022-26613 | Cri | 0.64 | 9.8 | 0.01 | Apr 6, 2022 | PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php. | ||
| CVE-2021-26114 | Cri | 0.64 | 9.8 | 0.02 | Apr 6, 2022 | Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | ||
| CVE-2022-28468 | Cri | 0.64 | 9.8 | 0.02 | Apr 5, 2022 | Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||
| CVE-2022-28467 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter. | ||
| CVE-2022-28116 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | ||
| CVE-2022-28115 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | ||
| CVE-2022-27304 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. | ||
| CVE-2022-27124 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||
| CVE-2022-27123 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter. | ||
| CVE-2022-26628 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter. |
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely.
- risk 0.64cvss 9.8epss 0.01
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
- risk 0.64cvss 9.8epss 0.01
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
- risk 0.64cvss 9.8epss 0.01
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
- risk 0.64cvss 9.8epss 0.01
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
- risk 0.64cvss 9.8epss 0.01
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
- risk 0.64cvss 9.8epss 0.07
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.
- risk 0.64cvss 9.8epss 0.08
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to…
- risk 0.64cvss 9.8epss 0.01
zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php.
- risk 0.64cvss 9.8epss 0.02
Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.
- risk 0.64cvss 9.8epss 0.01
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.
- risk 0.64cvss 9.8epss 0.02
Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.02
Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- risk 0.64cvss 9.8epss 0.01
Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter.
- risk 0.64cvss 9.8epss 0.01
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
- risk 0.64cvss 9.8epss 0.01
Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- risk 0.64cvss 9.8epss 0.01
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
- risk 0.64cvss 9.8epss 0.01
Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter.